Internal audits – Guidance on audits of management systems for biobanks, laboratories and inspection bodies
This document has been produced to provide biobanks, laboratories and inspection bodies with guidelines on how to set up a programme for the internal audit of their management systems and its application. This document has been revised in line with SS-EN ISO 203871, SS-EN ISO/IEC 170252, SS-EN ISO 151893 and SS-EN ISO/IEC 170204. Further guidance for conducting internal audits is given in the standard SS-EN ISO 190115.
This document uses the concept internal audit of management systems to emphasize the fact that audits are carried out by the organisation itself. Internal audits are often called first party audits as they are carried out by the organisation itself or contracted by the organisation itself.
2.1 Introduction
The word “shall” is used throughout this document to indicate the undertakings to be considered as mandatory, with reference to requirements in ISO/IEC 17020, ISO/IEC 17025, ISO 20387 and ISO 15189. The word “should” is used throughout this document to indicate the undertakings which, although not mandatory, to be considered by ILAC as a recognised means of compliance. The term “may” is used to indicate something that is allowed. The term “can” is used to indicate a possibility or an ability. Accredited bodies whose systems do not comply with the “should” guidance in this document can only be accredited if they can demonstrate to the accreditation body that their methodology is equivalent or better at fulfilling the relevant requirements of ISO/IEC 17020, ISO/IEC 17025, ISO 20387 and ISO 15189.
An accredited body shall establish and maintain a management system that has the ability to continuously meet the requirements of the relevant standard.
An accredited body shall draw up procedures for the implementation and documentation of internal audits.
The guidelines given in this document are general. The current procedure for internal audits of management systems and their application depends on the size, scope of activities and organisational structure of the accredited body.
2.2 Definitions
Quality Manager/Head of Quality/Quality Supervisor – Person who is responsible for the management system and its application and who reports directly to the top management.
Audit – Systematic, independent and documented procedure for obtaining objective evidence and evaluating it objectively to determine the extent to which audit criteria are fulfilled5
Auditor – Person who conducts an audit5. Where practically possible, auditors should be independent of the activity being audited and should always act in such a way that they are free of preconceived notions and conflicts of interest. SS-EN ISO/IEC 17020 requires the assurance that the auditor does not revise its own work. Professional accuracy and confidentiality shall also characterise the work of the auditor. The auditor shall have knowledge of auditing, current normative documents (for example, the relevant standard) and the accredited activities to be audited.
Audit programme – One or more audits planned to be performed over a certain period of time and for a specific purpose6
Audit plan – Description of activities and arrangements for an audit.6
2.3 Purpose of internal audits
An accredited body shall draw up procedures for internal audits for the purpose of verifying that it complies with the requirements of the respective accreditation standard and the accompanying normative documents and that the management system has been implemented and maintained in an appropriate manner. The purpose may also include the body’s own set requirements.
The non-conformities identified in an internal audit provide valuable data for improvements to the management system and should be used as starting points in the management’s review.
2.4 Audit programme
An audit programme shall be designed taking into account the importance of the processes and areas to be audited. The programme involves overall planning to cover a longer period of time, such as 4 years, but it also needs to be modifiable during the period with follow-ups and supplementary audits, for example.
An accredited body shall have an audit programme to cover all parts of the management system in a planned and systematic manner. It is not necessary to examine all parts of the management system or accredited methods/inspections in detail each year. The accredited body may choose to focus on a particular activity without completely neglecting the others. Internal audits should be performed at least annually. For inspection bodies there is a requirement of at least every 12 months.
The scope of an audit programme should be based on the size and extent of the audited organisation, as well as on the function, complexity and maturity of the management system. The programme should take into account the following:
a) the purpose and scope of the audit
- the frequency with which the audits should be carried out
- which areas the organisation has defined as critical, such as areas of high complexity, volume areas, etc., which may require more frequent intervals
- the location of the activities and any field activities
- standards, requirements in regulations and agreements and other audit criteria
- scope of accreditation
- known problem areas
- risks and consequences in the event of incorrect implementation
- issues related to implementation difficulties
- stakeholder points of view
Audit programmes for accredited activities may take into account and combine activities that correspond to the same personnel, skills, equipment, etc. However, the programme shall be sufficiently effective to ensure that the accredited body ensures the function and results of all the methods/inspections for which accreditation has been obtained.
The programme may include audits that take into account one or more management system standards. The audits can be conducted either separately or in combination.
In addition to established audit programmes, additional audits may be required. Such audits can be initiated by:
a) significant changes in governing documents, ways of working or organisation
- new activities for extended accreditation
- new branches/premises
- results and conclusions of previous audits
- customer complaints
- where an abnormal result is detected (e.g. when unacceptable results are reported in quality control, test or calibration comparisons);
For large accredited bodies, it may be an advantage to audit different parts of the management system at different times during the year. The person responsible for the audit programme should draw up, implement, monitor, review, and improve the audit programme, and, if necessary, provide the decision data for audit plans.
The organisation’s top management shall assign responsibility and authority for the management of the audit programme to one person. This person could be the quality manager (regardless of the job title). The designated person is responsible for planning the internal audits, but the implementation can be delegated.
It may be difficult to ensure the independence of the internal auditor in small organisations. Own internal work that cannot be assessed is, for example, completed accredited activities or a quality manager who examines aspects included in the area of responsibility for a quality manager. It may be necessary to engage individuals outside the small accredited body.
The person responsible for the audit programme may delegate auditing assignments to persons familiar with the management system of the accredited body and who know the requirements that apply for accreditation. All persons used in internal audits shall be qualified for the assignment, familiar with the applicable standard (including requirements in other regulations relevant to the accreditation) and have a general understanding of the auditing principles.
In large accredited bodies that perform activities of a wide range of areas, it may be necessary for internal audits to be performed by several persons under the management of the supervisor of the audit programme.
Audits performed by e.g. customers or the accreditation body cannot be considered to replace the accredited body’s own internal audits.
2.5 Audit plan
The lead auditor should design an audit plan where the degree of detail reflects the scope and complexity of the audit. The audit plan should cover or refer to, for example, the audit’s objectives and scope, reference criteria and any reference documents as well as auditing methods that will be used. The audit plan may contain different methodologies to achieve the purpose of the audits, it should ensure that both so-called horizontal and vertical audits are conducted.
In consultation with the audit group, the lead auditor should allocate work assignments and responsibilities as well as design work documents such as checklists, for example.
A horizontal audit is a detailed inspection to ensure that an element in the management system has been implemented in all activities within the body’s accreditation. Examples of such quality system elements are training of personnel, handling of standards, maintenance and calibration of equipment, methods, IT systems and instructions.
A vertical audit is a detailed inspection to ensure that all elements of the management system have been introduced when performing specific activities. For a vertical audit, a representative sample of work is randomly selected from cases that have recently been dealt with by the accredited body. Every part of the accredited body’s work associated with the selected activity should be inspected, including the following items, as appropriate:
a) tender, contract
- sample handling
- competence and authorisation of the personnel involved
- calibration and maintenance of equipment
- use of methods and instructions
- quality controls
- environmental conditions (premises, etc.) while work is carried out
- test/calibration reports, inspection/biobanking reports and reports of the results
- archiving of data and calculations that have been carried out.
A witnessing of practical work is a good way to demonstrate the real competence of the personnel and that the activity is carried out according to the specified instructions. Witnessing can be carried out at an internal audit as part of an audit programme or in another context under the requirement for monitoring/surveillance of personnel.
2.6 Carrying out internal audits
The individual responsible for the audit programme can be responsible for making final decisions regarding the objectives, scope and type of internal audits to be conducted. Such decisions can also be taken by the accredited body’s management, e.g. in conjunction with the management review. The responsibility for the decision making shall be defined in the management system.
The following activities should be included in the audit:
a) Draw up programme/plan for the current audit
- Conduct a document review (including method descriptions and reporting documents)
- Prepare audit of practical activities
- Conduct audit of practical activities
- Produce and distribute the audit report
- Review corrective actions
- Carry out any audit follow-up
In order to facilitate the implementation of the audit, the reporting method should be formalised to the necessary extent. For example, it may be practical to use standardised forms for the following:
a) the parts of the management system and the practical work that shall be audited
- notes of non-conformities and any corrective action
- summary of the results of the audit.
The results of an internal audit shall be based on objective facts.
The entire management system shall be reviewed within the framework of an audit programme. Special attention should also be paid to ensure the following:
2.6.1 Organisation
a) the responsibilities and authorisations of the management and personnel are specified and documented
- the organisation and management structure of the accredited body as well as its place in the main organisation are defined
2.6.2 Impartiality
a) risks to impartiality have been continuously identified and this has been documented
- the management and personnel are free from conflicts of interest that may affect the accredited activities
2.6.3 Management system
a) The management system’s manual and underlying documents are kept up to date. All requirements elements from standards and regulations have been incorporated and that external monitoring has worked so that any changes have been incorporated
- The management system’s manual and underlying documents are known and understood by the personnel
- quality policy and objectives are known and understood by the personnel
2.6.4 Document management
a) there are procedures for managing all documentation included in the system and that these procedures are followed
- only valid documents are used at the laboratory/inspection body and are available to all personnel affected
- valid documents are approved by an authorised person
- any amendments in the documents are traceable
2.6.5 Review of enquiries, tenders and contracts
a) there are procedures for reviews with customers and these procedures are followed
- these reviews are documented
2.6.6 Subcontractors
a) if an accredited body transfers part of an accredited activity to another body, there shall be information that shows that the subcontractors are competent to carry out the work and meet the requirements set out in relevant standards.
- there is detailed documentation for any work that has been given to another body and the subcontractors that have been engaged
- there is documentation that shows that the customer has received relevant information that subcontractors have been engaged
- there is documentation showing which subcontractors have been assessed and can be engaged
2.6.7 Purchase of services and goods
a) there are purchase documents for products that affect the quality of the activity at the accredited body and that the quality requirements set are met
- there are checks when products are received that affect the quality of activities
2.6.8 Complaints
a) there are procedures for how complaints that have been received are handled and they are also available to customers
- action taken by the accredited body as a result of a formal complaint follows the stipulated complaints procedure
- documentation of complaints is easily accessible, contains all necessary information and is kept up-to-date.
- complaints and other non-conformities are handled during the management review
2.6.9 Personnel
a) all personnel have relevant training and this training is documented
- information about relevant qualifications, training and experience of the personnel is documented and kept up-to-date
- there are relevant training programmes and these are followed
- documentation is available that shows the tasks that each individual may carry out
2.6.10 Premises and environmental conditions
a) there are suitable conditions in the environment where the accredited activity is carried out
- the environmental conditions are documented when these are important (this documentation should be studied to find out whether any measurements are carried out during conditions that do not meet environmental requirements)
- measurement equipment that is used to register environmental conditions is suitably calibrated
- the accessibility and usage of all spaces are inspected in a suitable way
2.6.11 Methods and method validation
a) methods are unambiguous and sufficiently detailed for what they are used for
- methods and instructions are up-to-date
- methods and instructions are available for the personnel and are used
- own methods and modified standard methods are validated and the validation data is available
- all calculations and data transfers have been correctly checked
- there are instructions for calculating/estimating measurement uncertainty and extended measurement uncertainty is calculated where relevant
- the instructions for producing own reference material are documented
- reference material and other reference standards are stored and labelled correctly
- the accredited body takes part, where appropriate, in relevant proficiency testing programmes
- new versions of standard methods have been reviewed, and, if these are introduced, confirmation has been circulated that work is being carried out in accordance with this latest version
2.6.12 Equipment
a) all equipment, including equipment that has been taken out of use, is numbered, labelled or identified in another way
- where the concept of traceability can be applied, reference equipment and reference standards have to be traceable to national or international standards (proof of this are valid calibration certificates or other documents that can prove the calibration status)
- reference standards are only used for calibration
- where relevant, the long-term stability of reference standards is investigated
- the internal calibration programme gives reassurance that all measurement/testing/inspection equipment and its working standards that may affect the validity of the accredited activities are correctly calibrated or verified, and that these activities are sufficiently well documented
- equipment and its working standards, where relevant, are inspected internally between calibrations
- the correct function of equipment and working standards that has been moved are inspected before it is used again for its intended purpose
- the programme for the maintenance of equipment and working standards is correctly applied to ensure that every object that is exposed to overloading or misuse, or that produces suspicious results or is shown to be faulty in some other way, is taken out of service, is repaired and is only used again once calibration or verification has shown satisfactory results
- maintenance of the equipment and working standards are documented in a sufficiently detailed manner
- written instructions for the use of the equipment are appropriate and are followed by the personnel that use the equipment
- computer programs are validated, have working procedures for back up and have instructions that are used and are understood by the operators
2.6.13 Sampling
a) there are instructions for sampling and these are available where work is performed and are followed
- samples are handled correct during the time between sampling and testing
2.6.14 Handling of materials, data, test items, calibration items and inspection items
a) there are instructions for identifying materials/data/items and these instructions are followed
- there are instructions for storing and preparing materials/data/items and these instructions are made available to the personnel and are followed
- the instructions for receiving, storing and discarding materials/data/items are followed.
2.6.15 Quality assurance of material, associated data and results of testing/calibration/inspection
a) there is a system for identifying any trends through method inspections, repeated measurements, etc.
- results from completed proficiency testing have been evaluated and any corrective action that is necessary has been taken
- in the absence of proficiency testing or certified reference materials, the accredited bodies shall find another way to show that the work carried out is correct
2.6.16 Reporting
a) reports are approved by the authorised person
- the reports contain all the necessary information
- original data and copies of reports are stored correctly for the specified period of time
- changes and additions to reports are clearly identified in a new document and include a reference to the original they replace
- requirements specifications when assessing conformity or comparisons with limit values are reported (for laboratories, possibly also the decision rule)
- in the cases where laboratory reports contain opinions and interpretations, that these are clearly distinguished in the reports as such, and that the grounds on which these are based are documented
- results from any tests carried out by subcontractors as well as any non-accredited measurements/testing/inspections shall be clearly marked
- electronic reporting systems are secure, that there are inspection systems that are followed to ensure there is no corruption/loss of data
2.7 Documentation of internal audits
Completed audits shall be documented in an appropriate manner.
The audit should be documented in a report containing the following information:
a) name of auditors
- date of the audit
- audited part of the system
- specification of the parts/areas that have been examined and how these are assessed to work
- all non-conformities that have been observed
The report and other documents linked to the audit should include the following information:
a) a fixed time limit for corrective action, and who is responsible for the implementation, as well as any agreed corrective action.
- date for confirming that corrective action has been taken
- the approval of the auditor or quality manager of the action taken.
The quality manager shall give reassurance that the audit report, and where appropriate, any individual non-conformities, are brought to the attention of the management.
Non-conformities identified shall be analysed, corrected and, if necessary, followed up. This is in order to ensure the elimination of the causes of non-conformities, so that these do not recur.
Whenever a non-conformity is discovered that may compromise the outcome of an accredited activity, the activities affected should be stopped until appropriate corrective action has been taken which has been shown to lead to satisfactory results. In addition, results that may have been affected by the noted non-conformity should be investigated and customers informed that the validity of the relevant calibration certificates, reports or certificates may be open to question.
Reports and records from internal audits shall be archived for the stipulated amount of time.
2.8 References
-
SS-EN ISO 20387:2021 Biotechnology – Biobanking – General requirements for biobanking (ISO 20387:2018) ↩
-
SS-EN ISO/IEC 17025:2018 General requirements for the competence of testing and calibration laboratories (ISO/IEC 17025:2017) ↩
-
SS-EN ISO 15189:2022 Medical laboratories - Requirements for quality and competence (ISO 15189:2022) ↩
-
SS-EN ISO/IEC 17020:2026 Conformity assessment — Requirements for bodies performing inspection (ISO/IEC 17020:2026) ↩
-
SS-EN ISO 19011:2026 Guidelines for auditing management systems (ISO 19011:2026) ↩ ↩2 ↩3
-
SS-EN ISO 9000:2026 Quality management — Fundamentals and vocabulary (ISO 9000:2026) ↩ ↩2